aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-21 08:04:49 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-21 08:04:49 -0400
commit17a2edf9be3d1144db1a262c5358bf190c9b272b (patch)
treec6eb1fdf9e1a0b0326493f63f55b6dcff22e415d
parentMerge branch 'master' of http://github.com/netblue30/firejail (diff)
downloadfirejail-17a2edf9be3d1144db1a262c5358bf190c9b272b.tar.gz
firejail-17a2edf9be3d1144db1a262c5358bf190c9b272b.tar.zst
firejail-17a2edf9be3d1144db1a262c5358bf190c9b272b.zip
Add a profile for arch-audit
-rw-r--r--README.md2
-rw-r--r--arch-audit.profile40
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 42 insertions, 1 deletions
diff --git a/README.md b/README.md
index efc102ba1..c9e04ee3c 100644
--- a/README.md
+++ b/README.md
@@ -180,4 +180,4 @@ calligraflow, calligraplan, calligraplanwork, calligrasheets, calligrastage,
180calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd, google-earth, 180calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd, google-earth,
181imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron, 181imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron,
182ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart, 182ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart,
183conky 183conky, arch-audit
diff --git a/arch-audit.profile b/arch-audit.profile
new file mode 100644
index 000000000..d8ed64811
--- /dev/null
+++ b/arch-audit.profile
@@ -0,0 +1,40 @@
1# Firejail profile for arch-audit
2# This file is overwritten after every install/update
3quiet
4# Persistent local customizations
5include /etc/firejail/arch-audit.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9
10noblacklist /var/lib/pacman
11
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc
16
17caps.drop all
18ipc-namespace
19netfilter
20no3d
21nodvd
22nogroups
23nonewprivs
24noroot
25nosound
26notv
27novideo
28protocol unix,inet,inet6
29seccomp
30shell none
31
32disable-mnt
33private
34private-bin arch-audit
35private-dev
36private-tmp
37
38memory-deny-write-execute
39noexec ${HOME}
40noexec /tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 95fc14d04..e4e3e4972 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -20,6 +20,7 @@ amarok
20amule 20amule
21android-studio 21android-studio
22apktool 22apktool
23arch-audit
23ardour4 24ardour4
24ardour5 25ardour5
25arduino 26arduino